7.5
CVSSv2

CVE-2003-1131

Published: 31/12/2003 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in index.php in KnowledgeBuilder, referred to as KnowledgeBase, allows remote malicious users to execute arbitrary PHP code by modifying the page parameter to reference a URL on a remote web server that contains the code.

Vulnerable Product Search on Vulmon Subscribe to Product

activecampaign knowledgebuilder 3.0.1

activecampaign knowledgebuilder 2.0.1

activecampaign knowledgebuilder 2.1.0

activecampaign knowledgebuilder 2.1.4

Exploits

source: wwwsecurityfocuscom/bid/9292/info KnowledgeBuilder is prone to a remote file include vulnerability An attacker could exploit this to cause hostile PHP scripts to be included and executed from a remote server This would occur in the security context of the web server hosting the software wwwexamplecom/kb/indexphp?pag ...